> Nice sarcasm but you’re not actually addressing a solution to the problem I raised.
Are you not concerned about an asteroid impact rendering you extinct during your next Rust build? Why not? That's the same level of relevance as your supposed concern.
> So you’re now saying it’s ok to have exploits compiled into your application as long as it’s sandboxed?
You need to act like it is compromised in all cases, just like everything else.
> I wonder how customers of your application feel about that? I’m certainly not going to be entering my bank details into your ecommerce platform (to give just one obvious example why your suggestion wouldn’t work).
So your version is "we trust everyone and don't verify anything". Yeah, that's going to work. By your "logic" firewalls wouldn't be necessary.
> Are you not concerned about an asteroid impact rendering you extinct during your next Rust build? Why not? That's the same level of relevance as your supposed concern.
That’s a strawman argument and you’re still dodging the question.
> You need to act like it is compromised in all cases, just like everything else.
No. I act like compromised code is a legitimate risk regardless of how well your build pipeline is sandboxed.
I don’t understand why this is a hard concept for you to grasp.
> So your version is "we trust everyone and don't verify anything". Yeah, that's going to work. By your "logic" firewalls wouldn't be necessary.
That’s the literal opposite of my point (as well as another strawman).
I was replying to someone who suggested sandboxing by raising a couple of places their suggestion falls short.
Did you even read this thread? Or just assumed “anyone suggesting sandboxing wouldn’t work must be an idiot”? Because you’ve managed to misrepresent my comments at every opportunity.
You’re not even attempting to
discuss the topic, more interested in make meta attacks about me personally. So I think it’s now safe to assume you’re just trolling. In which case I’ll return the favour by adding you to the ignore list.
Pity though, I would have been interested to talk to someone who was passionate about this topic.
Are you not concerned about an asteroid impact rendering you extinct during your next Rust build? Why not? That's the same level of relevance as your supposed concern.
> So you’re now saying it’s ok to have exploits compiled into your application as long as it’s sandboxed?
You need to act like it is compromised in all cases, just like everything else.
> I wonder how customers of your application feel about that? I’m certainly not going to be entering my bank details into your ecommerce platform (to give just one obvious example why your suggestion wouldn’t work).
So your version is "we trust everyone and don't verify anything". Yeah, that's going to work. By your "logic" firewalls wouldn't be necessary.